Description
An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via cacheName to SystemCacheDetails.jsp.
Remediation
References
https://cybersecurityworks.com/zerodays/cve-2019-20364-openfire.html
https://github.com/igniterealtime/Openfire/pull/1561
https://issues.igniterealtime.org/browse/OF-1955
Related Vulnerabilities
CVE-2021-42010 Vulnerability in maven package org.apache.heron:heron-api
CVE-2021-23384 Vulnerability in npm package koa-remove-trailing-slashes
CVE-2022-0672 Vulnerability in maven package org.eclipse.lemminx:lemminx-parent
CVE-2022-36886 Vulnerability in maven package org.jenkins-ci.plugins:external-monitor-job
CVE-2022-31108 Vulnerability in maven package org.webjars.npm:mermaid